1. Corporate Scope & Identification of Data Fiduciary
This Privacy Policy forms an integral and legally enforceable agreement between you (the "User", "Subscriber", "Customer", or "Data Principal") and HostAsia Cloud Technologies (hereinafter referred to as "HostAsia", "we", "us", or "our"), having its registered server infrastructure and principal operations in Mumbai, Maharashtra, India.
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), HostAsia acts as a Data Fiduciary in respect of your account identity, billing records, and subscriber profile. For customer server data, virtual machines, database contents, and email hosting stored by you on our cloud infrastructure, HostAsia operates as a Data Processor, processing such data solely upon your configuration and instruction.
Platforms Covered by this Policy:
This Policy applies unconditionally to our primary portal (hostasia.in), international website (hostasia.com), Client Billing Panel (userpanel.hostasia.in), SuperAdmin consoles, automated provisioning APIs (/api/v1), and all associated bare-metal, VPS, cloud hosting, and domain registration modules.
2. Legal & Regulatory Compliance Framework
HostAsia operates under strict adherence to Indian and international statutory standards, including:
Statutory adherence to fair processing, explicit notice, purpose limitation, parent/guardian consent verification for minors, and automated data breach notifications to the Data Protection Board of India.
Under Indian Computer Emergency Response Team directives, VPS, Cloud, and Hosting providers are mandated to maintain subscriber records and IPv4/IPv6 assignment access logs for a mandatory minimum of 5 years.
Implementation of reasonable security practices, ISO/IEC 27001 parity, cryptographic storage, and designated statutory Grievance Officer compliance under Rule 5(9).
For citizens of the European Economic Area (EEA), HostAsia adheres to Standard Contractual Clauses (SCCs), lawful basis definitions under Article 6, and transparent data subject rights.
3. Categories of Personal Data Collected
We collect and hold personal information only where necessary to provision cloud infrastructure, combat fraud, and fulfill statutory tax and telecom record-keeping obligations:
| Data Category | Specific Data Attributes Collected |
|---|---|
| Identity & Account Data | Full legal name, email address, mobile/WhatsApp phone number, physical billing address, state/province, country, and salted bcrypt/argon2 password hashes. |
| Commercial & Tax Data | Company/Entity name, GST Identification Number (GSTIN), PAN (where statutory deduction applies), and verified electronic invoicing addresses. |
| Technical & Telemetry Data | Client originating IP address, browser User-Agent header, operating system fingerprint, API authorization keys (ha_live_...), and session authentication timestamps. |
| Server Infrastructure Logs | cPanel, WHM, and Virtualizor control panel logins, SSH console access timestamps, IP allocation assignments, reverse DNS entries, and SMTP relay transaction logs. |
| Domain Registration Records | Registrant Name, Organization, Postal Address, Phone Number, and Administrative/Technical Contact details mandated by ICANN and Registry operators (e.g., NIXI for .IN). |
4. Lawful Grounds & Purpose of Processing
In compliance with Section 4 of the DPDP Act 2023 and Article 6 of the GDPR, HostAsia processes personal data strictly under established lawful grounds:
- Contractual Performance: Creating your account, provisioning cloud servers, executing automated hypervisor deployments, routing DNS records, generating invoices, and processing client support tickets.
- Statutory & Tax Obligations: Generating GST-compliant e-invoices, fulfilling CERT-In 5-year log retention directives, and complying with court orders under Section 91 of the Code of Criminal Procedure (CrPC).
- Fraud Prevention & Network Defense: Real-time heuristic scanning to prevent phishing deployments, outbound DDoS botnets, crypto-mining abuse on cloud VPS, and payment gateway chargeback fraud.
- Explicit Consent: Sending non-critical maintenance announcements, promotional tier upgrades, and optional developer API credential issuance. Consent may be revoked anytime via your Client Dashboard.
5. Domain Registration, ICANN, NIXI & WHOIS Protocols
When you register, renew, or transfer a top-level domain (TLD) through HostAsia:
1. Registry Escrow & Transfer: ICANN (Internet Corporation for Assigned Names and Numbers), registry operators (e.g. NIXI for .IN, Verisign for .COM), and upstream registrar partners (such as Spaceship / Namecheap) require registrant contact information for legal ownership validation and Registry Data Escrow (RDE).
2. WHOIS Privacy Protection: Where supported by the respective TLD registry, HostAsia enables free WHOIS Privacy Protection by default. Your personal phone number, physical address, and personal email are replaced with a proxy privacy alias in public RDAP/WHOIS directories.
3. Registry Exceptions: Certain country-code TLDs (such as .IN, .CO.IN, .US) have statutory registry policies that prohibit masking or require designated local contact verification under applicable national registry mandates.
6. Payment Processing & PCI-DSS Financial Handling
HostAsia operates under strict tokenized payment protocols:
- PCI-DSS Compliant Aggregators: Financial payments (UPI, RuPay, Visa, Mastercard, NetBanking, PayPal, International Cards) are handled directly through certified PCI-DSS Level 1 payment gateways (Razorpay, Stripe, PayPal).
- Zero Raw Card Storage: HostAsia’s database stores only the masked card suffix (e.g. Ending in 4242), the cardholder's bank name, transaction reference IDs, and payment statuses. No CVV or card PIN ever traverses or resides on our application servers.
- Statutory Invoicing: Tax invoices featuring your GSTIN, HSN/SAC codes (998315 for web hosting), state supply codes, and calculated CGST/SGST/IGST are archived for seven (7) financial years pursuant to the Central Goods and Services Tax (CGST) Act, 2017.
7. Datacenter Infrastructure & Technical Security Measures
Your data is housed in enterprise-grade, certified facilities with multi-layered perimeter and cryptographic protections:
Technical Defenses Deployed:
- End-to-end TLS 1.3 encryption across all client portal dashboards and administrative endpoints.
- AES-256 cryptographic encryption for database backups, API secrets, and sensitive credentials.
- Automated edge Anti-DDoS rate-limiting and SYN flood scrubbing mitigating up to 1.2 Tbps attacks.
- Strict Role-Based Access Control (RBAC) ensuring internal staff only access telemetry upon authorized support ticket escalations.
9. Data Retention & Erasure Schedules
HostAsia retains personal data only as long as necessary to fulfill service provisioning or comply with statutory retention laws:
| Data Record Type | Retention Period | Statutory Justification |
|---|---|---|
| Active Account Profile | Duration of active subscription + 180 days post-termination | Account recovery and service continuity. |
| Server & IP Access Logs | 5 Years (Mandatory) | CERT-In Directives (Govt of India mandate). |
| Financial Tax Invoices | 7 Financial Years | Indian GST Act & Income Tax Act, 1961. |
| Support Ticket Transcripts | 3 Years from resolution | Quality assurance and contractual dispute resolution. |
| Terminated VPS Backups | Purged after 7 days | Automatic disk shredding post-grace period. |
10. Your Statutory Rights as a Data Principal
Under the DPDP Act, 2023 and the GDPR, you possess the following actionable rights regarding your personal information:
To exercise any of these rights, email our Grievance Desk at privacy@hostasia.in using your verified registered account email address.
11. Law Enforcement, CERT-In & Subpoena Guidelines
HostAsia maintains a strict, transparent protocol regarding requests from law enforcement agencies, cyber cells, and statutory judicial bodies:
1. Mandatory Legal Process: We do not disclose subscriber telemetry or customer information to any third party or governmental entity without a formal, legally verified written request issued under Section 91 of the CrPC, a formal directive from CERT-In, or a valid order signed by a competent judicial magistrate in India.
2. Emergency Imminent Harm Exception: In bona fide emergencies involving imminent physical danger, child sexual abuse material (CSAM), or critical national security emergencies, HostAsia will cooperate with designated cyber investigation authorities within statutory parameters.
3. Customer Notification: Unless strictly prohibited by statutory gag order, non-disclosure order, or sealed court directive, HostAsia aims to notify affected subscribers of legal data demands relating to their accounts.
12. Statutory Grievance Redressal & Data Protection Officer (DPO)
In compliance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and Section 8(9) of the Digital Personal Data Protection Act, 2023, the designated statutory officer for HostAsia is: